Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Dream

CTI Researcher

Dream

CTI Researcher advancing threat intelligence for Dream’s sovereign AI and national cyber-defense platform. Analyzing adversary infrastructure, attribution, EASM, and STIX knowledge.

Posted 8/23/2026full-timeTel Aviv • 🇮🇱 IsraelMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Cyber Threat Intelligence, with a strong focus on STIX 2.1, MITRE ATT&CK, and the ability to analyze and enrich data using Python. Capable of producing actionable intelligence reports and collaborating effectively across teams to enhance threat detection and response.

Highest-signal resume keywords
Cyber Threat IntelligenceSTIX 2.1Python AnalysisOpen-Source Intelligence (OSINT)Threat-Intelligence Writing

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat Actor AttributionAdversary Infrastructure AnalysisIndicators of Compromise (IoC)Domain/IP RelationshipsTLS/PKIData NormalizationEvidence DisciplineActive Validation TechniquesAnalytical SkillsThreat Analysis
Soft Skills
Collaborative MindsetCuriosityMethodical ApproachAttention to DetailImpact-Driven
Tools & Technologies
MLOpsGitData Quality StandardsVersion Control SystemsReputation Systems
Industry Keywords
EASMPhishing InfrastructureGovernance StandardsData ProvenanceThreat Briefs

Tech Stack

Tools & technologies
CloudDNSPandasPython

About the role

Key responsibilities & impact
  • Execute the CTI research roadmap across threat actor attribution, adversary infrastructure analysis, EASM insights, and STIX-based knowledge management
  • Conduct in-depth infrastructure and campaign analysis, including domain/IP relationships, hosting patterns, and certificates
  • Identify, validate, and track Indicators of Compromise and emerging threats using passive sources and approved active techniques
  • Normalize, enrich, deduplicate, and maintain intelligence in STIX 2.1, aligned with internal ontology and quality standards
  • Collaborate with Engineering, MLOps, and Data teams to translate intelligence into actionable intelligence, alerts, and customer-facing outputs
  • Produce intelligence reports, threat briefs, watchlists, and early-warning assessments for internal teams and customers
  • Support investigations by providing contextual analysis, confidence scoring, and evidence-backed assessments
  • Ensure adherence to governance, ethics, sourcing, provenance, and data-quality standards across intelligence outputs

Requirements

What you’ll need
  • 3–6+ years of experience in Cyber Threat Intelligence, SOC/IR intelligence support, EASM, or adversary infrastructure analysis
  • Strong understanding of DNS, IPs, ASNs, hosting/cloud providers, TLS/PKI, domain lifecycle, and phishing infrastructure
  • Hands-on experience with open-source and commercial CTI sources (OSINT, feeds, telemetry, reputation systems)
  • Practical knowledge of STIX 2.1, MITRE ATT&CK, and TAXII
  • Ability to perform passive discovery and controlled active validation, with a focus on accuracy, evidence discipline, and noise reduction
  • Experience using Python for analysis and enrichment, including pandas and notebooks
  • Strong analytical and threat-intelligence writing skills, able to translate technical findings into clear, actionable insights
  • Comfortable working in a collaborative, version-controlled environment using Git, with attention to documentation and reproducibility
  • Curious, methodical, and impact-driven mindset with a strong sense of intelligence rigor and accountability

Benefits

Comp & perks
  • Remote/hybrid work arrangement (job header states “Remote Tel Aviv Hybrid”)